Описание
The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to delete arbitrary comment
Ссылки
- Release Notes
- Patch
- ExploitThird Party Advisory
- Release Notes
- Patch
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.2.1 (исключая)
cpe:2.3:a:woocommerce:woocommerce:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 56%
0.00339
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 4.3
github
около 2 лет назад
The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to delete arbitrary comment
EPSS
Процентиль: 56%
0.00339
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-863